An AI tool can look perfect in the demo. It automates your replies, predicts your stock, drafts your proposals, and never complains. But before you connect it to your customer data, ask yourself one question: if this tool leaked or misused that data, would you survive it?

For a small business, one data breach or one misuse of customer information can destroy the trust that took years to build. The good news is that vetting an AI tool does not require a legal team. It requires asking the right questions before you sign up. Here is a practical checklist.

Start With the Basics: Who Made It and How Long Will It Last?

AI startups appear and disappear fast. A tool that does not exist next year is a bigger risk than an imperfect tool with a long track record. Check who is behind the company, how they are funded, and how long they have been operating. Read the news, not just the homepage. If the company looks unstable, consider whether your data is safe with it long term.

The Five Questions That Matter Most

  1. Where is my data stored, and where is it processed? Data stored in one country may be subject to different laws than data stored in another. Ask directly and get a written answer.
  2. Is my data used to train the model? Some tools train their AI on customer data. Ask whether your data is excluded from training, or whether you can opt out.
  3. Who can access my data? Does the vendor have employees or contractors who can see it? Do they subprocess data to third parties?
  4. How is my data encrypted, both in transit and at rest? You want encryption when data moves to their servers and while it sits there.
  5. What happens to my data if I leave? Can you export everything, and is it deleted from their systems when you cancel?

If a vendor hesitates, gives vague answers, or points you to a wall of legalese, treat that as a red flag. Good vendors have clear, plain-language answers to all five questions.

Check the Paperwork, Then Double Check It

  • Privacy policy — does it explain what data is collected and why? Does it allow them to use your data for purposes beyond providing the service?
  • Terms of service — what are your rights? Can they terminate you easily? Who owns the output the tool generates from your data?
  • Data Processing Agreement (DPA) — for any serious tool this should be available. It defines who processes what and the safeguards.
  • Compliance certifications — look for recognised security certifications and standards. These signal that the vendor takes security seriously.

If the tool touches sensitive categories like health, financial, or identity data, be extra careful. In Sri Lanka, the Personal Data Protection Act (PDPA) now sets obligations for how personal data must be handled. A tool that does not understand basic data protection is not a tool you should trust.

The Principle of Least Data

The simplest way to protect customer data is to give the AI tool only what it genuinely needs. Ask yourself: does this tool need full customer names, or would a reference number do? Does it need phone numbers, or only first names? The less data you hand over, the less there is to lose if something goes wrong.

This applies to the AI provider's model too. Before you paste customer details into a public chat interface to ask for help, remember that public prompts may be used for training. Use the tool's private or zero-retention modes where available.

Practical Red Flags

  • No privacy policy, or a privacy policy that is copy-paste vague.
  • No clear answer on whether your data trains their model.
  • No way to export your data, or charges you to leave.
  • Requires unnecessary permissions or access to data it should not need.
  • Recent security incidents, data breaches, or major controversy you can find with a quick search.

Final Thoughts

You do not need to become a security expert to use AI responsibly. You need to ask five good questions, read the policy that matters, and hand over only the data that is required. That small amount of diligence protects the trust you have worked hard to earn.

Every tool you adopt should be able to answer those five questions in writing. If it cannot, the cheapest AI tool is expensive insurance, and the safe choice is walking away.